CWE-620— Unverified Password Change
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.— MITRE CWE catalog
101 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-620page 2 of 3
- CVE-2025-61536HIGHCVSS 8.2EG 8.22025-10-16
FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/l…
- CVE-2025-22381HIGHCVSS 8.2EG 8.22025-10-16
Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.
- CVE-2024-27715HIGHCVSS 8.2EG 8.22024-07-05
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the Password Change mechanism.
- CVE-2026-76633HIGHCVSS 8.1EG 8.12026-08-20
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclus…
- CVE-2026-42084HIGHCVSS 8.1EG 8.12026-05-04
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password…
- CVE-2026-40588HIGHCVSS 8.1EG 8.12026-04-21
blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not verify the user's existing password before accepting a new one…
- CVE-2024-13373HIGHCVSS 8.1EG 8.12025-03-01
The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.1. This is due to the plugin not properly validating a user's identity prior to updating their …
- CVE-2025-13148HIGHCVSS 6.5EG 8.12025-12-11
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another user without prior knowledge of that password.
- CVE-2022-2930HIGHCVSS 7.8EG 7.82022-08-22
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
- CVE-2026-54175HIGHCVSS 7.6EG 7.62026-08-20
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm i…
- CVE-2025-11235HIGHCVSS 7.5EG 7.52026-01-07
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.…
- CVE-2022-21935HIGHCVSS 7.5EG 7.52022-06-15
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
- CVE-2026-46623HIGHCVSS 7.4EG 7.42026-06-26
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the p…
- CVE-2024-34077HIGHCVSS 7.3EG 7.32024-05-14
MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset another user's password and takeover their account, if the victim has an …
- CVE-2026-17599HIGHCVSS 7.2EG 7.22026-08-07
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead o…
- CVE-2026-54801HIGHCVSS 7.2EG 7.22026-07-09
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials w…
- CVE-2026-27757HIGHCVSS 7.2EG 7.22026-02-27
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenti…
- CVE-2023-5844HIGHCVSS 7.2EG 7.22023-10-30
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
- CVE-2021-34785HIGHCVSS 6.5EG 7.22021-09-09
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
- CVE-2026-85591HIGHCVSS 7.1EG 7.12026-09-04
phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with ses…
- CVE-2025-61132HIGHCVSS 7.1EG 7.12025-10-23
A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_ex…
- CVE-2025-59808MEDIUMCVSS 6.8EG 6.82025-12-09
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise …
- CVE-2023-25931MEDIUMCVSS 6.4EG 6.82023-03-01
Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially result in unauthori…
- CVE-2026-86260MEDIUMCVSS 6.5EG 6.52026-09-07
A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of t…
- CVE-2026-54176MEDIUMCVSS 6.5EG 6.52026-08-20
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccountIn…
- CVE-2025-46389MEDIUMCVSS 6.5EG 6.52025-08-06
CWE-620: Unverified Password Change
- CVE-2024-41796MEDIUMCVSS 6.5EG 6.52025-04-08
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF att…
- CVE-2023-4465MEDIUMCVSS 6.5EG 6.52023-12-29
A vulnerability, which was classified as problematic, was found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE…
- CVE-2021-34786MEDIUMCVSS 6.5EG 6.52021-09-09
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
- CVE-2021-22773MEDIUMCVSS 6.5EG 6.52021-07-21
A CWE-620: Unverified Password Change vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all …
- CVE-2019-25653MEDIUMCVSS 5.5EG 6.22026-03-30
Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characte…
- CVE-2024-21757MEDIUMCVSS 6.1EG 6.12024-08-13
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.…
- CVE-2026-44733MEDIUMCVSS 5.9EG 5.92026-06-26
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements. A password validation fla…
- CVE-2024-45647MEDIUMCVSS 5.6EG 5.62025-01-20
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.
- CVE-2025-4552MEDIUMCVSS 5.4EG 5.42025-05-12
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/user/1/password. The manipulation leads to unverified passwo…
- CVE-2025-4903MEDIUMCVSS 5.3EG 5.32025-05-19
A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the function sub_41F4F0 of the file /H5/webgl.asp?tggl_port=0&remote_management=0&http_passwd=game&exec_service=admin-resta…
- CVE-2024-51493MEDIUMCVSS 5.3EG 5.32024-11-05
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that has gained temporary control over an authenticated victim's Octo…
- CVE-2024-8794MEDIUMCVSS 5.3EG 5.32024-09-24
The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a user's identity prior to setting a passwo…
- CVE-2023-4915MEDIUMCVSS 5.3EG 5.32023-09-13
The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the passwor…
- CVE-2026-105785MEDIUMCVSS 4.8EG 4.82026-10-05
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-…
- CVE-2026-8327MEDIUMCVSS 4.3EG 4.32026-05-21
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo::update() without field whitelisting r…
- CVE-2025-3849MEDIUMCVSS 4.3EG 4.32025-04-22
A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password chan…
- CVE-2023-4381MEDIUMCVSS 4.3EG 4.32023-08-16
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- CVE-2025-3793MEDIUMCVSS 4.2EG 4.22025-04-24
The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' fun…
- CVE-2024-23637MEDIUMCVSS 4.2EG 4.22024-01-31
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repea…
- CVE-2025-47938LOWCVSS 3.8EG 3.82025-05-20
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password …
- CVE-2024-2213LOWCVSS 3.3EG 3.32024-06-06
An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current…
- CVE-2026-9249LOWCVSS 3.1EG 3.12026-05-26
Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 202…
- CVE-2026-2543LOWCVSS 2.7EG 2.72026-02-16
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects unknown code of the file inc/mod/pages.php of the component Password Change Handler. The manipulation of the argument Password leads to unverifie…
- CVE-2025-46748LOWCVSS 2.7EG 2.72025-05-12
An authenticated user attempting to change their password could do so without using the current password.
Map vulnerabilities like CWE-620 to your infrastructure
EchelonGraph correlates every CVE — across CWE-620 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →